Splunk RCE Vulnerability Exposes Systems to Arbitrary Shell Command Execution by Attackers
A high-severity Remote Command Execution (RCE) vulnerability has been identified in Splunk Enterprise and Splunk Cloud Platform, posing significant security risks.
A high-severity Remote Command Execution (RCE) vulnerability has been identified in Splunk Enterprise and Splunk Cloud Platform, posing significant security risks.
Designated as CVE-2026-20163 with a CVSS score of 8.0, this vulnerability enables unauthorized execution of shell commands on the host operating system.
Classified under CWE-77, the flaw underscores the risks associated with improper input neutralization in enterprise software.
The vulnerability is located within the platform's REST API, specifically at the /splunkd/__upload/indexing/preview endpoint.
When files are uploaded to Splunk, a preview occurs before database indexing. During this preview phase, a parameter called unarchive_cmd is used.
Due to inadequate sanitization of input to this parameter, attackers can inject shell commands. The system may execute these commands during file processing.
Designated as CVE-2026-20163 with a CVSS score of 8.0, this vulnerability enables unauthorized execution of shell commands on the host operating system.
Exploitation requires access to a user account with the edit_cmd capability. Though standard users cannot exploit this, a compromised administrator account could lead to server takeover.
This vulnerability affects multiple versions of both on-premises and cloud deployments. Administrators should verify their versions against the affected list:
Splunk Enterprise 10.0: Versions 10.0.0 through 10.0.3 Splunk Enterprise 9.4: Versions 9.4.0 through 9.4.8 Splunk Enterprise 9.3: Versions 9.3.0 through 9.3.9 Splunk Cloud Platform: Versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.24
The Splunk Enterprise 10.2 component is not affected by this REST API flaw.
Administrators should prioritize patching to mitigate potential risks of arbitrary command execution.
Splunk has released security updates to address input sanitization issues across affected versions.
Upgrade Splunk Enterprise 10.0 environments to version 10.0.4. Upgrade Splunk Enterprise 9.4 environments to version 9.4.9. Upgrade Splunk Enterprise 9.3 environments to version 9.3.10. For Splunk Cloud Platform users, patches are being applied directly to hosted instances.
Based on reporting by GBHackers.
